Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
riverdroid
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Claude Tried to Hack 30 Companies. Nobody Asked It To
(trufflesecurity.com)
2 points
by
riverdroid
6mo ago
|
2 comments
2.
▲
I found a backdoor into my bed
(trufflesecurity.com)
980 points
by
riverdroid
2y ago
|
385 comments
3.
▲
by
riverdroid
2y ago
I would also love to use it this way in Go. Currently we dump SQLite compatible schema to use for SQLite powered integration tests even though we use postgres when live. It allows us to have zero dependency sub-second integration tests usin
4.
▲
TruffleHog now finds all Deleted and Private Commits on GitHub
(trufflesecurity.com)
15 points
by
riverdroid
2y ago
|
2 comments
5.
▲
by
riverdroid
2y ago
While most mesothelioma (a rare cancer) is known to be caused by asbestos and not other agents, asbestos is known to cause other cancers of the lung, larynx, and ovary, with limited evidence of some other cancers as well. https://
6.
▲
New Google OAuth Vulnerability
(trufflesecurity.com)
2 points
by
riverdroid
3y ago
|
0 comments
7.
▲
by
riverdroid
3y ago
I was researching this recently and came across this article: https://pganalyze.com/blog/gin-index The GIN index has some similarities to Elasticsearch's inverted indices (last I knew anyway), which also can be qu
8.
▲
A new XSS Hunter, that finds additional vulnerabilities
(trufflesecurity.com)
2 points
by
riverdroid
4y ago
|
0 comments
9.
▲
Protecting Cloud SQL data with external backups using cloudsql-exporter
(trufflesecurity.com)
2 points
by
riverdroid
4y ago
|
0 comments
10.
▲
by
riverdroid
4y ago
One important factor to consider about these 'whiplash' events is that they also deplete the immediate water carrying capacity as the top soil washes away. The top soil normally serves as a 'water battery', and allows th
11.
▲
by
riverdroid
4y ago
https://web.archive.org/web/20230113192401/https://www.econo...
12.
▲
Of-CORS: a framework for hacking internal apps with open CORS
(trufflesecurity.com)
5 points
by
riverdroid
4y ago
|
0 comments
13.
▲
by
riverdroid
4y ago
The easiest and best way for you (you'll get updates through signed packages, etc) is probably to install via the Ubuntu Software Center. Though it can be difficult to download and run random software from the internet, I have to say,
14.
▲
by
riverdroid
4y ago
Current Ford F-150 towing capacity is 5,000 to 11,300 lbs depending on the package. Most people probably don't need long range peak towing capacity. Seems like the feature set could be useful to a lot of people, probably most, maybe no
15.
▲
by
riverdroid
4y ago
Besides that, lots of incident response work to figure out the scope and impact of the breach, I'd imagine.
16.
▲
TruffleHog v3 – Detect and automatically verify over 600 credential types
(github.com)
84 points
by
riverdroid
4y ago
|
8 comments
17.
▲
by
riverdroid
5y ago
Be aware of platforms publishing a 'proxy' phone number so they can still collect their fees: https://www.theverge.com/2019/8/6/20756878/yelp-grubhub-comm...
18.
▲
by
riverdroid
5y ago
What do you use to produce this analysis?
19.
▲
by
riverdroid
5y ago
SMS is not strong enough, especially for protecting ALL of your 2FA codes + passwords. SIM swapping attacks frequently occur, and it doesn't even have to be with your carrier.
20.
▲
by
riverdroid
5y ago
This is a big improvement to supplement the existing docs, but how does one know what the parameter types are without wading deep into the implementation or trial and error? This has been a major point of frustration for me when interacting
21.
▲
by
riverdroid
5y ago
Thanks for the revocation resources! I was not aware of LE's revocation API. Seems like maybe reporting should get built in as an option.
22.
▲
by
riverdroid
5y ago
If you search GitHub, you can find ~4M results for PEM private keys: https://github.com/search?q=PRIVATE+KEY-----&type=Code Many are for tests and don't go to anything. Some go to really important things though, ev
23.
▲
by
riverdroid
5y ago
Most private keys in Git repositories seem to be test data. But why are those test private keys sometimes used for other things? Probably just people lazily copying from ~/.ssh/idrsa or copying to ~/.ssh/idrsa.
24.
▲
by
riverdroid
5y ago
Many of these committed keys are test fixtures in repositories. As for how that happened, not entirely sure, but I am guessing that people just grabbed a key lying around like ~/.ssh/idrsa
25.
▲
by
riverdroid
6y ago
I'd say typing is even more important when you are using other people's code with your code. It's also a huge productivity boost too when the relevant methods and types are available to you, the editor almost writes the code
26.
▲
by
riverdroid
6y ago
From my limited experience, resources are better spent to SEO to boost ranking. Also, you can request review on google ads keywords to prevent competitors from using your name, especially if you have a trademark.
27.
▲
by
riverdroid
6y ago
There might be some software issues at play with some modern AWD systems that I am not aware of, but it's traditionally a mechanical issue with 4WD and AWD. 4WD has a physical link, so having two different diameters linked stresses the
28.
▲
by
riverdroid
6y ago
Be aware that the air quality sensor on most units is a cheap VOC sensor. It detects gasses, not particles. It'll trigger if you fart near it or cook something odorous, but not for dust or smoke. I have the Winix 5300 and 5500 purifier
29.
▲
by
riverdroid
6y ago
Seems like it could go both ways, couldn't it? Free ranging birds are in less proximity and healthier conditions. There is less contact between them, more sanitary conditions, and healthier birds. But yes, they could have more contact
30.
▲
by
riverdroid
6y ago
I know vitamin D is inexpensive to manufacture, but with all of this new demand, I really hope that there is testing going on. I would not be surprised if Amazon has a bunch of fake supplements mixed into their supply chain for example. The
More ›